Latest Tech News

Stay updated with the latest in technology, AI, cybersecurity, and more

Filtered by: clickfix Clear Filter

From ClickFix to MetaStealer: Dissecting Evolving Threat Actor Techniques

By John Hammond, Alden Schmidt, Lindsey Welch During the past fifteen business days, Huntress analysts have observed increased threat activity involving several notable techniques. One case involved a malicious AnyDesk installer, which initially mimicked a standard ClickFix attack through a fake Cloudflare verification page but then utilized Windows File Explorer and an MSI package masked as a PDF to deploy MetaStealer malware. Additionally, two incidents involving the Cephalus ransomware vari

Inside a Real Clickfix Attack: How This Social Engineering Hack Unfolds

An inside look at a ClickFix campaign and a real-world attack, its next iteration (FileFix), and how to prevent it in its tracks, before device compromise. ClickFix: Silent Copying to Clipboard ClickFix, a deceptive social engineering tactic, is used by threat actors to manipulate unsuspecting users into unwittingly allowing a web page to silently populate the clipboard. Ultimately, the attacker is attempting to get a user to (unknowingly) execute malicious code, gathered from the browser and

New FileFix attack weaponizes Windows File Explorer for stealthy commands

A cybersecurity researcher has developed FileFix, a variant of the ClickFix social engineering attack that tricks users into executing malicious commands via the File Explorer address bar in Windows. FileFix, a variation of the social-engineering attack called ClickFix, allows threat actors to execute commands on the victim system through the File Explorer address bar in Windows. Cybersecurity researcher mr.d0x discovered the new method and demonstrated that it could be used in attacks targeti